🕒 Created · Updated

The Department of Justice seized internet domains to disable a Chinese state-sponsored hacking group targeting U.S. critical infrastructure.

The Department of Justice announced the seizure of three internet domains used by the Chinese state-sponsored hacking group QTFY. This action effectively disabled the group's primary hacking platforms, QScan and QTRouter, which were used to target sensitive networks including NASA, the Federal Reserve, the U.S. Senate, and various defense contractors. The hacking group, employed by the China-based company Nanjing Xinjiuwei Network Technology Co., was used by the People's Republic of China's Ministry of State Security and the People's Liberation Army to blend malicious traffic with routine consumer internet activity. Attorney General Todd Blanche stated that the seizures were necessary to stop and prosecute malicious hackers preying on America's critical infrastructure. The group's operations, which began in 2018, successfully breached several Department of Energy national laboratories, the National Institutes of Health, and a Department of Health and Human Services agency. While the full impact of the spying effort remains private due to security concerns, the administration's move highlights the ongoing cyber-espionage tension between the United States and China.

Sources